Return to Threats

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

thehackernews.com 2026-09-06 malicious AI use Medium

What Happened

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

Why It Matters

According to the report, Elastic Security Labs documented four REVSTEALER-linked Windows programs that persist after the primary stealer removes itself; one disables Windows Update and Microsoft Defender to run a cryptocurrency miner. These modules, named ProManager, WinUpdate, SoftManager, and an unnamed fourth, are traditional malware components focused on system persistence, defense evasion, and cryptomining rather than AI-specific functionality. RealGround analysis: while this is not an AI-native threat, similar persistence and defense-evasion techniques could be used to target AI infrastructure (e.g., disabling host defenses on servers running AI agents or models). Organizations should ensure endpoint protection, configuration hardening, and monitoring extend to AI-related hosts and pipelines so that commodity malware cannot become a pivot into AI systems.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html

Talk to AI CISO